CTT Report Hub
3.43K subscribers
9.91K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
21-07-2022

eSentire Threat Intelligence Malware Analysis: Gootloader and IcedID

https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-gootloader-and-icedid

Actors/Campaigns:
Xinglocker

Threats:
Gootloader
Icedid
Cobalt_strike
Process_hollowing_technique
Pingpull
Antidebugging_technique
Sandbox_evasion_technique
Conti
Quantum_locker
Quantum_tool

Industry:
Financial

Geo:
Apac, America, Africa, Emea

IOCs:
Registry: 6
Domain: 1
File: 2
Hash: 4

Softs:
active directory

Algorithms:
exhibit

Functions:
Foad, WriteProcessMemory, GetTickCount, GetComputerNameExW, GetUserNameW, Test, GetAdaptersInfo

Languages:
java, php

YARA: Found
#ParsedReport
21-07-2022

LockBit 3.0 Update \| Unpicking the Ransomwares Latest Anti-Analysis and Evasion Techniques

https://www.sentinelone.com/labs/lockbit-3-0-update-unpicking-the-ransomwares-latest-anti-analysis-and-evasion-techniques

Actors/Campaigns:
Blackmatter

Threats:
Lockbit
Cobalt_strike
Socgholish_loader
Uac_bypass_technique
Blackcat
Egregor
Antidebugging_technique
Conti
Process_injection_technique

Industry:
Financial

Geo:
Russian, Ukraine

TTPs:

IOCs:
Hash: 6
Domain: 19

Softs:
thebat, powerpnt, steam, encsvc, dbsnmp, windows service, onenote, msexchange, zcash, wordpad

Algorithms:
xor, exhibit

Functions:
NtSetInformationThread
#ParsedReport
21-07-2022

Buy, Sell, Steal, EvilNum Targets Cryptocurrency, Forex, Commodities

https://www.proofpoint.com/us/blog/threat-insight/buy-sell-steal-evilnum-targets-cryptocurrency-forex-commodities

Actors/Campaigns:
Evilnum (motivation: information_theft)
Venom_spider

Industry:
Financial

IOCs:
Domain: 8
File: 7
Url: 11
Path: 1
Hash: 5
Email: 5

Softs:
windows defender, microsoft word

Languages:
java
#ParsedReport
21-07-2022

Attackers target Ukraine using GoMet backdoor

http://blog.talosintelligence.com/2022/07/attackers-target-ukraine-using-gomet.html

Threats:
Gomet_dropper

Industry:
Government

Geo:
Ukrainian, Ukraine, Russian, Ukrainians

CVEs:
CVE-2020-5902 [Vulners]
Vulners: Score: 10.0, CVSS: 4.6,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- f5 big-ip access policy manager (<11.6.5.2, <12.1.5.2, <13.1.3.4, <14.1.2.6, le15.0.1.4, <15.1.0.4)
- f5 big-ip advanced firewall manager (<11.6.5.2, <12.1.5.2, <13.1.3.4, <14.1.2.6, <15.0.1.4, <15.1.0.4)
- f5 big-ip advanced web application firewall (<11.6.5.2, <12.1.5.2, <13.1.3.4, <14.1.2.6, <15.0.1.4, <15.1.0.4)
- f5 big-ip analytics (<11.6.5.2, <12.1.5.2, <13.1.3.4, <14.1.2.6, <15.0.1.4, <15.1.0.4)
- f5 big-ip application acceleration manager (<11.6.5.2, <12.1.5.2, <13.1.3.4, <14.1.2.6, <15.0.1.4, <15.1.0.4)
have more...
CVE-2022-1040 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- sophos sfos (le18.5.3)


IOCs:
File: 6
Hash: 3
Path: 1
IP: 1

Softs:
task scheduler

Links:
https://github.com/Laeeth/GoMet
#ParsedReport
21-07-2022

The Return of Candiru: Zero-days in the Middle East

https://decoded.avast.io/janvojtesek/the-return-of-candiru-zero-days-in-the-middle-east/?utm_source=rss&utm_medium=rss&utm_campaign=the-return-of-candiru-zero-days-in-the-middle-east

Threats:
Watering_hole_technique
Devilstongue

Geo:
Palestine, Yemen, Lebanon, Turkey

CVEs:
CVE-2022-2294 [Vulners]
Vulners: Score: Unknown, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix


IOCs:
Domain: 11
Path: 30
Registry: 4

Softs:
google chrome, chrome, chromium

Algorithms:
rsa-2048, aes-256-cbc

Languages:
java, Javascript

Links:
https://github.com/avast/ioc/tree/master/Candiru
#ParsedReport
21-07-2022

Brazen, Unsophisticated and Illogical: Understanding the LAPSUS$ Extortion Group

https://www.tenable.com/blog/brazen-unsophisticated-and-illogical-understanding-the-lapsus-extortion-group

Actors/Campaigns:
Lapsus (motivation: information_theft, script_kiddie, politically_motivated, cyber_criminal)
Karakurt (motivation: information_theft)
Ransomhouse

Threats:
Conti
Empire_loader
Godfather
Silence
Avoslocker
Lockbit

Industry:
Telco, Financial, Media, Healthcare, Government

Geo:
America, Brazil, Portugal

IOCs:
File: 2

Softs:
tiktok, confluence, telegram, active directory, microsoft sharepoint
Попробовал повысить качество вытаскивания функций WIN API из отчетов. Посмотрим что получится )))
#ParsedReport
22-07-2022

The Return of Candiru: Zero-days in the Middle East

https://decoded.avast.io/janvojtesek/the-return-of-candiru-zero-days-in-the-middle-east

Threats:
Watering_hole_technique
Devilstongue

Geo:
Lebanon, Yemen, Turkey, Palestine

CVEs:
CVE-2022-2294 [Vulners]
Vulners: Score: Unknown, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix


IOCs:
Domain: 11
Path: 30
Registry: 4

Softs:
chrome, chromium, google chrome

Algorithms:
aes-256-cbc, rsa-2048

Languages:
javascript

Platforms:
apple

Links:
https://github.com/avast/ioc/tree/master/Candiru
#ParsedReport
22-07-2022

OperationShadowTiger

https://mp.weixin.qq.com/s/jX8D8d-4q46pKHS0AIVgjw

Actors/Campaigns:
Shadowtiger
Tiger_hibiscus

Threats:
Dll_hijacking_technique
Putty_tool
Uacme

Geo:
Korean, Korea, Asia, Asian, Polish

CVEs:
CVE-2018-6055 [Vulners]
Vulners: Score: 6.8, CVSS: 4.9,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- google chrome (<64.0.3282.119)


TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 19
Url: 3
Email: 2
IP: 5
Hash: 16

Softs:
chrome

Languages:
php
#ParsedReport
22-07-2022

Proxyware. Attackers who make money using ProxyWare

https://asec.ahnlab.com/ko/36762

Threats:
Dropper/win.proxyware.c5173477
Dropper/win.proxyware.c5173478
Dropper/win.proxyware.c5210584

IOCs:
File: 8
Path: 1
Hash: 7

Softs:
ms-sql

Algorithms:
base64

Functions:
startMainRoutine

Platforms:
x86
#ParsedReport
22-07-2022

Alibaba OSS Buckets Compromised to Distribute Malicious Shell Scripts via Steganography

https://www.trendmicro.com/en_us/research/22/g/alibaba-oss-buckets-compromised-to-distribute-malicious-shell-sc.html

Actors/Campaigns:
Teamtnt

Threats:
Monero_miner
Xmrig_miner
Kinsing_miner

Geo:
Chinese

IOCs:
Domain: 1
Hash: 5

Softs:
unix, redis

Links:
https://github.com/xmrig/xmrig
#ParsedReport
22-07-2022

Qakbot Resurfaces with new Playbook

https://blog.cyble.com/2022/07/21/qakbot-resurfaces-with-new-playbook

Threats:
Qakbot
Brata
Beacon
Process_injection_technique

Industry:
Financial

TTPs:
Tactics: 2
Technics: 4

IOCs:
File: 5
Hash: 5

Softs:
android

Algorithms:
base64
Всем привет.
До 1 августа уходим вместе с движком публикации TI-отчетов в отпуск.
Все индикаторы из отчетов продолжат попадать в наш фид автоматически.
winapi_funcs.yml
564 KB
Постепенно выхожу из стазиса.
Напарсил с https://docs.microsoft.com/en-us/windows/win32/api/ список WIN API.
Методы интерфейсов тоже собрал, но пока решил не выкладывать из-за ненадобности )

Как же я долго не хотел прикручивать HyperScan от Intel к парсеру отчетов, но теперь придется.
Кстати ,вот регулярка, которая тоже помогает выявить название WIN API функции в тексте (^| )((Alpc|Cc|Cm|Dbg|Dbgk|Em|Etw|Ex|FsRtl|Hv|Hvl|Io|Kd|Ke|Kse|Lsa|Mm|Nt|Ob|Pf|Po|PoFx|Pp|Ppm|Ps|Rtl|Se|SH|Sm|Tm|Ttm|Vf|Vsl|Wdi|Wfp|Whea|Wmi|Zw)([A-Z][a-z]+){3,}[A-Z]?)([., ]|$)